Question 134 of 464
N10-009 Network Security Practice Question
A company wants to allow inbound HTTPS traffic to a web server located in the DMZ from the Internet. The firewall has three interfaces: Inside (corporate network), Outside (Internet), and DMZ (web server). Which of the following firewall rules is required?
⚠ Common exam trap
Test-takers frequently confuse the direction of the traffic flow, mistakenly thinking the rule should allow traffic from the DMZ to the Outside (Option B) because they focus on the server sending responses, rather than the client initiating the connection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Allow traffic from Outside to DMZ on port 443
The correct rule is to allow traffic from the Outside (Internet) interface to the DMZ interface on TCP port 443 (HTTPS). This permits inbound web requests to reach the web server while keeping the corporate Inside network isolated. The firewall must explicitly permit this traffic because the default implicit deny rule would otherwise block all inbound connections from the Outside zone.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Allow traffic from Outside to DMZ on port 443
Why this is correct
This firewall rule explicitly permits inbound connections originating from the "Outside" network (representing the public internet) to destination IP addresses within the "DMZ" (Demilitarized Zone). By specifying port 443, the rule exclusively allows HTTPS traffic, which is the standard secure protocol for web communication. This directly fulfills the requirement to allow secure web access to a server hosted in the DMZ from external users.
- ✗
Allow traffic from DMZ to Outside on port 443
Why it's wrong here
This firewall rule would allow systems within the "DMZ" to initiate outbound connections to the "Outside" network (the Internet) using port 443. This is typically used for services like fetching updates or communicating with external APIs. However, this rule does not permit *inbound* connections from the Outside to the DMZ, meaning external clients would still be unable to establish an HTTPS session with the web server.
When this WOULD be correct
This option would be correct if the question required allowing the web server in the DMZ to initiate outbound HTTPS connections to the Internet, for example, to download updates or access external APIs.
- ✗
Allow traffic from Inside to DMZ on port 443
Why it's wrong here
This rule would permit traffic originating from the "Inside" network (representing the internal corporate LAN) to reach servers located in the "DMZ" on port 443. While it would allow internal users to access the web server via HTTPS, it completely fails to address the core requirement of allowing *inbound* HTTPS traffic from the *Internet* (Outside). Therefore, it does not solve the problem of making the web server publicly accessible.
When this WOULD be correct
This option would be correct if the question asked for a rule to allow internal corporate users (Inside) to access a web server in the DMZ for management or internal applications.
- ✗
Allow traffic from Outside to Inside on port 443
Why it's wrong here
This rule would permit inbound traffic originating from the "Outside" network (Internet) to directly access resources within the "Inside" network (internal corporate LAN) on port 443. This configuration completely bypasses the security segmentation provided by the DMZ and exposes internal systems directly to the public internet. Such a rule poses a significant security risk and is contrary to the best practice of isolating public-facing services in a DMZ.
When this WOULD be correct
This rule would be correct if the web server were located on the Inside interface (corporate network) and the company wanted to allow inbound HTTPS from the internet directly to that internal server, though this is generally discouraged due to security risks.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.
✓Allow traffic from Outside to DMZ on port 443Correct answer▾
Why this is correct
This firewall rule explicitly permits inbound connections originating from the "Outside" network (representing the public internet) to destination IP addresses within the "DMZ" (Demilitarized Zone). By specifying port 443, the rule exclusively allows HTTPS traffic, which is the standard secure protocol for web communication. This directly fulfills the requirement to allow secure web access to a server hosted in the DMZ from external users.
✗Allow traffic from DMZ to Outside on port 443Wrong answer — click to see why▾
Why this is wrong here
The question asks for a rule to allow inbound HTTPS traffic from the Internet to the web server in the DMZ. Option B allows traffic from DMZ to Outside, which is outbound, not inbound, and does not permit the initial connection from the Internet.
★ When this WOULD be the correct answer
This option would be correct if the question required allowing the web server in the DMZ to initiate outbound HTTPS connections to the Internet, for example, to download updates or access external APIs.
Why candidates choose this
Candidates may confuse the direction of traffic or think that allowing return traffic from the DMZ is necessary for the inbound connection, not realizing that stateful firewalls automatically permit return traffic for established connections.
✗Allow traffic from Inside to DMZ on port 443Wrong answer — click to see why▾
Why this is wrong here
The question specifies inbound HTTPS traffic from the Internet to a web server in the DMZ, so the rule must allow traffic from Outside to DMZ, not from Inside to DMZ.
★ When this WOULD be the correct answer
This option would be correct if the question asked for a rule to allow internal corporate users (Inside) to access a web server in the DMZ for management or internal applications.
Why candidates choose this
Candidates may confuse the direction of traffic or think that internal users need access to the DMZ web server, overlooking that the question explicitly states traffic originates from the Internet.
✗Allow traffic from Outside to Inside on port 443Wrong answer — click to see why▾
Why this is wrong here
The question specifies the web server is in the DMZ, not the Inside network. Allowing traffic from Outside to Inside on port 443 would bypass the DMZ and expose the internal corporate network to inbound internet traffic, violating security best practices.
★ When this WOULD be the correct answer
This rule would be correct if the web server were located on the Inside interface (corporate network) and the company wanted to allow inbound HTTPS from the internet directly to that internal server, though this is generally discouraged due to security risks.
Why candidates choose this
Candidates may confuse the DMZ with the Inside network or assume that HTTPS traffic should be allowed to any internal server, overlooking the specific placement of the web server in the DMZ as stated in the question.
Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 11, 2026
This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.